What the vulnerability does
01Description
Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through <= 4.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in SearchIQ SearchIQ searchiq allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SearchIQ: from n/a through <= 4.4.
Explanation of Vulnerability in Simple Terms
SearchIQ versions 4.4 and earlier lack proper authorization checks, allowing unauthenticated attackers to read sensitive information through network requests. The vulnerability requires no user interaction and can be exploited remotely. Affected installations should upgrade to version 5.1 or later to remediate the issue.
What an attacker can do
Read sensitive information from the application without authentication.
Potential impact on your site
Confidential data may be exposed to unauthenticated users if SearchIQ is deployed on your site.
Conditions required to exploit
Network access to the SearchIQ instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities